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SYSTEM AND METHOD FOR DEVELOPING SOFTWARE 
UTILIZING DETERMINATIVE REPRESENTATIONS 

FIELD OF THE INVENTION 

The present invention relates generally to models and representations utilized in 
generating software. More particularly, the present invention relates to a system for and a method 
of creating software utilizing a deterministic model or a representation of a complex control 
system. 
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BACKGROUND OF THE INVENTION 

Software often must be designed and developed as part of a large and complex 
reactive system. A reactive system is utilized in a variety of applications, such as, 
telecommunications, automobiles, computer networks, personal computers, avionic systems, 
process controls, man-machine interfaces, and other systems. Generally, reactive systems are 
event driven and continuously react to external and mternal stimuli. The external and internal 
stimuli can be human operator initiated or can be provided from completely external equipment or 
happenings. 

One type of reactive system is a graphical user interface for flight plan editing in a 
graphical flight management system (FMS). Developing software for a reactive system, such as, 
the graphical user interface, requires that the behavior of the reactive system be modeled or 
represented in a formal fashion. 

Generally, the reactive system can be modeled or represented as a state machine. A 
state machine is an abstract control model consisting of a set of states, a set of input events, a set of 
output actions and a state transition fiinction. A fiinction takes the current state and an input event 
and returns a set of output events and the next state. Some states may be designated as "terminal 
states." A terminal state is an ending state from which the state machine does not exit. 

The state machine can also be viewed as a fiinction which maps an ordered sequence 
of input events into a corresponding sequence of (sets of) output events. State machines are often 
represented by state transition diagrams to effectively specify the behavior of reactive systems. 
Statecharts are a type of state transition diagram described in more detail below. Statecharts 
efficiently represent a set of states and the transition between states based upon events. The 
graphical notation associated with statecharts is easily understandable and can be utilized to support 
discussions and conversations about the system. Such a representation or graphical notation is 
highly valuable when evaluating the workings of a graphical user interface. 

State machines can be deterministic or non-deterministic. A deterministic state 
machine is one where the next state is uniquely determined by a single input event. A non- 
deterministic state machine may have several possible next states for a given input event. The next 
state that is actually chosen may either be chosen randomly or it may be chosen based upon an 
arbitrary number of subsequent input events. In the latter case, until these subsequent events 
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occur, it is not possible to determine the state within which the machine resides. It is generally 
possible to automatically translate a non-deterministic state machine into a deterministic one which 
will produce the same ou^ut given the same input. 

Sunple statecharts or state transition diagrams, such as deterministic finite 
automations (DFA), have been utilized to study languages, such as programming languages. The 
goal of such simple state transition diagrams is to allow the state machine to determine whether or 
not a given word is contained in a language. A DFA has a finite set of states and transitions where 
each transition leads from one state to another. Each transition is associated with a particular input 
character; the transition can only cause a change in the active state when that particular input 
character is read from the input word. At any given time, only one of the states is active, i.e., the 
next input character (read from the word to be recognized) is able to activate only those transitions 
that depart from the active state. 

One state is the designated start position (it is active state when the first input 
character is read). One or more states are defined as terminating states. After the input word has 
been read completely, if the state machine has arrived to a terminating state, the word is accepted. 
Otherwise, the word is rejected (i.e., not in the language recognized by the DFA), The set of 
languages that can be recognized by DFAs equals the set of languages that can be described using 
regular expressions. Therefore, this set of languages is called regular languages. 

Several extensions of more advanced concepts of state transition systems have been 
proposed. Some extensions introduce more complex languages than regular languages and others 
better support tasks not related to programming languages. As a trend of controlling systems by 
computers and software increases, many more systems are represented as being state based. Using 
automations and state transition diagrams to specify these systems becomes increasingly more 
popular and effective. A significant difference between the described conventional extensions and 
more advanced concepts to state transition systems when compared to DFAs is that these extensions 
do not include a terminating state. Although these computer systems can be switched off and thus 
are forced to terminate, these systems no longer recognize or reject words of finite length. 

DFAs are not appropriate for more complex application which do not include 
terminating states. With the exception of certain military applications, the complex systems are 
often designed so that they can potentially operate forever. Although it is possible to specify 
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behavior of a complex system such as a graphical interface (GUI) using DFAs, an exceedingly 
large number of transitions and states is necessary due to global options and parallel execution, 
respectively. 

Another difference between the described conventional extensions and more 
advanced concepts is that state transitions in complex systems are not triggered by characters read 
from an input word as in a DFA system. Rather, external events drive the systems. For example, 
external events can be keystrokes, expiration of timers, arrival of messages from another computer, 
sensor signals, mouse clicks, etc. These events are called external because their source is outside 
of the state machine. The events are also discrete in that they either occur or do not occur. Events 
which are recognized by the state machine can lead to changes or transitions in the state. Events 
that are not recognized do not cause a change in the active state (the system continues to run in its 
present active state). There is no equivalence of rejecting an input word as utilized in a DFA. 

Generally, non-deterministic statecharts can be converted to an equivalent 
deterministic statechart if both machines recognize the same language. However, the deterministic 
statechart becomes extremely complex because the definition of equivalence of automations is not 
helpful. Also, there is a need for a deterministic statechart that can provide a specification for a 
reactive system. One type of statechart system utilizes a Harel statechart which is fully described 
in Harel, "Statecharts: A Visual Formalism for Complex Systems" Science of Computer 
Programming 8 (1987), pp. 231-274. Harel statecharts are well known by one of ordinary skill in 
the art. However, Harel statecharts are not deterministic. There is nothing in its rules which 
prevent two different states from being the result of the same input criteria. 

Thus, there is a need for a deterministic state machine defmed by statecharts. 
Further, there is a need for a deterministic statechart that can be used to design complex reactive 
systems, such as, avionic software. Further still, there is a need for a modified Harel statechart 
which is deterministic. 
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SUMMARY OF THE INVENTION 

An exemplary embodiment relates to a statechart for use in the development of 
avionic software. The avionic software requires deterministic behavior. The statechart includes a 
first state, a second state and a third state. The third state includes the first and second parallel 
states. The first state is ordered with respect to the second state. The state chart does not allow 
parallel states to be an ordered to ensure deterministic behavior of the statechart. 

Another embodiment relates to a modified Harel statechart formed an a computer. 
The modified Harel statechart includes a mathematical representation of a group of states. The 
group of states mcludes a first state including a plurality of ordered parallel states. The 
mathematical representation ensures deterministic operation. 

Still another embodiment relates to a computer code for statechart editor. The 
computer code includes code for generating a graphical representation of a state including parallel 
states and code for ordering the parallel states. 

Still another embodiment relates to a method of providing avionic software. The 
method includes providing a graphical representation of a state, and applymg the graphical 
representation to an execution engine to create the avionic software. The state includes a plurality 
of parallel states which are ordered with respect to each other. The parallel states are ordered so 
that only one of the parallel states is active in response to a particular event. 

Yet still another embodiment relates to a statechart for use in the development of 
software for an application. The statechart includes a first state means, a second means, and a third 
state means. The first state means represents a first condition of the software in the application. 
The second state means indicates a second condition and is within the first state means. The third 
state means represents a third condition and is also within the first state means. The third state 
means is ordered with respect to the second state means. 


PATENT 
99CR125/KE 


BRffiF DESCRIPTION OF THE DRAWINGS 

Exemplary embodiments will hereafter be described with reference to the 
accompanying drawings, wherein like numerals denote like elements, and: 

FIGURE 1 is a schematic block diagram of a system for generating software in 
accordance with an exemplary embodiment the program system including a statechart editor; 

FIGURE 2 is a schematic block diagram of a statechart for use in the system 
illustrated in FIGURE 1; 

FIGURE 3 is a schematic drawing of a screen utilized by the statechart editor 

illustrated in FIGURE 1; and 

FIGURE 4 is a schematic block diagram of a statechart including a tree structure in 
accordance with still another exemplary embodiment of the present invention. 
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DETAILED DESCRIPTION OF PREFERRED EXEMPLARY EMBODIMENTS 

In FIGURE 1, a system 10 includes a software engine 12, a control unit 20 and an 
operator interface 24. System 10 can be a software/hardware system for avionics applications, 
such as flight management systems (FMS) capable of flight planning fimctions. Alternatively, 
system 10 can be utilized in other complex reactive systems. 

Control unit 20 includes a statechart editor 32, a script editor 34, scripts 35, 
statecharts 36, a runtime environment 38, and a script interpreter 40. Control unit 20 can be a 
STAR/graphical control display unit. Control unit 20 serves as a translator for interpreting 
commands from interface 24 and providing instructions to engine 12. The various states associated 
with system 10 exist in unit 20. Interface 24 can allow the user to visualize these various states as 
discussed in more detail below. 

Interface 24 is any system which allows user commands to be input into system 10. 
Interface 24 can include keyboards, keypads, mouse devices, trackballs, joysticks or other 
interfaces. Interface 24 can be a VIVID/GUI interface which includes a graphical editor and 
prototype development tool for avionics displays. 

Engine 12 can be an actual Flight Management System or a VISTA/FMS engine. 
The VISTA/FMS engine is an aircraft simulation software tool which provides fimctions associated 
with an FMS, such as, flight planning. 

Statechart editor 32 is a software tool capable of creating and revising graphical 
representations of statecharts 36 through interface 24 or through a computer. Graphical statechart 
editor 32 can create statecharts 36 which are executed by runtime environment 38. Preferably, 
statecharts 36 are fully deterministic and can advantageously be utilized for avionics software 
development, such as, flight maintenance systems. Editor 32 is preferably an editor capable of 
graphically editing and defining states and transitions for system 10. 

Run time environment 38 is a hardware or software tool capable of executing 
statecharts 36. Run time environment 38 executes statecharts 36 and interacts with engine 12 to 
operate a state machine in accordance with statecharts 36. 

Script editor 34 is a textural editor capable of creating and editing scripts 35. Scripts 
35 are executed by script interpreter 40. Script interpreter 40 can be closely related to run time 
environment 38. 
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With reference to FIGURE 2, an exemplary statechart 50 of statecharts 36 (FIGURE 
1) is shown. Statechart 50 is a graphical representation that can be edited or created on editor 32. 
Statechart 50 includes a superstate 51, a state 76 and a state 78. Superstate 51 includes a parallel 
state 52 and a parallel state 54. Parallel state 52 includes a substate 56 and substate 66, and parallel 
state 54 includes a substate 58 and substate 68. State 78 includes a substate 86 and substate 88. 

When the state machine (partially represented by statechart 50) is in superstate 51, 
the state machine can be either in parallel state 52 or parallel state 54. From substate 56 of parallel 
state 52, the state machine enters a substate 66 upon an event A. From substate 66 of parallel state 
52, state machine enters a substate 56 upon an event B. From substate 56 of parallel state 52, state 
machine enters state 76 upon event E, thereby leaving parallel state 52 and superstate 51. 

Similarly, from substate 58 of parallel state 54, the state machine enters substate 68 
upon an event C. From substate 68 of parallel state 54, the state machine enters substate 58 upon 
an event D. From substate 68 of parallel substate 54, the state machine enters state 78 upon event 
E leaving parallel state 54 and superstate 51. 

The described transitions are all readily ascertamable from the graphical 
representation of statechart 50 shown in FIGURE 2. Statechart 50 allows events, states and 
substates to be analyzed in a convenient fashion. For example, the state machme enters state 76 or 
state 78 from superstate 51 upon an event E, depending upon the state within which the machine 
resides (substate 56 or substate 68). If the state machine is in substate 56 of parallel state 52 and in 
substate 68 of parallel state 54, it enters state 76 upon an event due to the priority of parallel state 
52 over parallel state 54, 

As shown in FIGURE 2, various graphical symbols convey information about the 
operation of the state machine. For example, rectangles represent superstates, or substates and 
arrows represent events. Superstate 51 includes several states such as states 56, 58, 66 and 68. 
Dashed line 70 indicates that superstate 51 is a parallel superstate including two parallel states 52 
and 54. Superstate 51 including parallel states 52 and 54 has all of its parallel states 52 and 54 
active when superstate 51 is active. State 78 only has one of substates 86 or 88 active because 
substates 86 and 88 are not parallel states. 

Superstate 51 can include several more parallel states. In addition, any of substate 
56, 58, 66, 68, 86 and 88 or states 76 and 78 can include parallel states. Unlike parallel states as 
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defined by Harel, statechart 50 has an order or priority to parallel states 52 and 54 to ensure that 
statechart 50 is determinative. That is, left-to-right ordering can be utilized wherein the same event 
(e.g., event E) can cause the entry into two states 76 and 78. The left-to-right priority indicates 
that state 76 will be entered when the state machine resides in substates 56 and 68 upon event E. 
Alternatively, a subscript notation can be utilized in each of parallel states 52 and 54 to indicate the 
priority of parallel states 52 and 54. In another embodiment, an up and down orientation or right- 
to-left orientation can determine the priority between parallel states 52 and 54. More complex 
embodiments of statecharts can also be utilized. 

When state 78 is active, either state 88 or 86 is active. When parallel states 54 52 
are active, one of substate 56 or 66 and one of substate 58 or 56 is active. The graphical notation 
wherein superstate 51 encompasses parallel states 52 and 54 simplifies the logical demonstration of 
statechart 50. 

Substate 56 can also include a history element 82. History element 82 is utilized to 
indicate that substate 56 should be entered the next time parallel state 52 is entered. For example, 
if state 56 was exited when the state machine entered state 76 upon event E, the next time the state 
machine enters parallel state 52 it enters state 56 as opposed to state 66 as symbolized by history 
element 82. Similarly, state 58 can be associated with a history element 84. 

With reference to FIGURE 3, a screen 150 for provision by statechart editor 32 
(FIGURE 1) is disclosed. Screen 150 includes a superstate 152 (flight deck). Superstate 152 
includes a parallel state 154 (auto pilot), a parallel state 156 (weight on wheels), and a parallel state 
158 (MFD). Parallel state 154 includes a substate 162 (engaged) that includes a parallel substate 
164 (lateral) and a parallel substate 166 (vertical). Parallel state 154 also includes a substate 155 
(disengage) that includes a history element 157. Parallel substate 164 includes a substate 168 
(FMSLNAV), a substate 170 (approach), a substate 172 (heading), and a substate 174 (lateral off). 
Substate 174 includes a history element 176. 

Parallel substate 166 includes a substate 180 (glide scope), a substate 182 
(FMSVNAV), a substate 184 (altitude), and a substate 186 (vertical off). Substate 186 includes a 
history element 188. Substate 184 also includes a substate 192 (intercept), a substate 194 (altitude 
hold), and substate 196 (FL change). Substate 196 includes history element 198. 
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Parallel state 156 includes a substate 202 (no) and a substate 204 (yes). Substate 204 
includes a history element 206. Parallel state 158 includes a substate 210 (flight progress), a 
substate 212 (EICAS), and substate 214 (map). Substate 210 includes a history element 216. 

As can be seen on screen 150 in FIGURE 3, when superstate 152 is active (state 
machine resides in superstate 152), one substate in each of parallel states 154, 156 and 158 is 
active. The particular example shown in FIGURE 3, includes substate 155, substate 204 and 
substate 210 in an active state. For simplicity, screen 150 is not shown with events associated with 
the various states. 

In FIGURE 4, a statechart 300 similar to statechart 50 includes superstate 302 (R). 
Superstate 302 includes a state 304 (B) including a parallel state 306 (C) and a parallel state 308 
(D). Parallel state 306 includes a substate 312 (E) and a substate 314 (F). Parallel state 308 
includes a substate 316 (G) and a substate 318 (H). State 302 also includes a state 320 (A) and a 
state 330 (I). The state relationship can be represented in a simplified tree structure 340 in 
FIGURE 4 where arrows represent the relationship between states. 

As shown in tree structure 340, superstate 302 includes state 304, state 320 and state 
330. State 304 includes parallel states 306 and 308. Parallel state 306 includes states 312 and 314. 
Parallel states 308 include states 316 and 318. Events are not shown in statechart 300 for 
simplicity. 

A mathematical discussion describes the concepts behind the advantageous statechart 
system discussed with reference to FIGURE 2. The mathematical discussion provides notations for 
describing the syntax associated with statecharts. The syntax is provided as an exemplary 
embodiment only and is not shown to limit the scope of the claims. 

Statecharts Syntax 

Notation: 

1. States: S-{sj,..,sJ 

2^x{^A©}x2(^^) 

2. Hierarchy: p:S^Kj 2^x{X0R}xS 

u {terminal} 
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3. Events: £ = {ei,...,e^}u{ej 

4. Actions: A = {^^ } 

5. History States: S^j^t <=S 

6. Transitions: Tc:2^xEx2^xA 

The number of states (n) is, of course, finite; therefore, we can enumerate the states 
(1). Each state can either be terminal (leaf), i.e. it has no substates, state 76 or it can be further 
divided into substates, (e.g. superstate 51, parallel states 52 and 54, and state 78) thereby defining 
a hierarchy. Substates can be of two types: AND and XOR decomposition. XOR decomposition 
defines hierarchy; whenever the parent state (e.g., state 78) is active, exactly one of its substates 
(e.g. substates 86 or 88) is active, too (thus XOR), This is used to refine a general parent state. A 
default state needs to be specified to determine which of the substates becomes active should the 
parent state be activated. 

AND decomposition is used to define parallel states (e.g., parallel states 52 and 54). 
Whenever the parent state (e.g., superstate 51) is active, all of its substates (parallel states 52 and 
54) are active, too (AND). There is no need for a default state. Instead, a total order for the 
substates has to be specified; this is what the relation is for (<^e SxS). Notation (2) shows the 
hierarchy function p that, for each state, defines it to be a terminal state or a parent state of AND 
or XOR substates, with a default state in the latter case. 

Notations (3) and (4) enumerate the events and actions. There is no distinction 
between internal and external actions or events, respectively. Cq is the designated empty event 
which indicates that none of the actual events has occurred. Notation (5) lists the history states. 
Notation (6) defines the transitions. Transitions consist of a source set of states that have to be 
active before the transition can become active, a triggering event, a target state set and a resulting 
action. 
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Definition: (Descendants) 

For a set of states S, a state sgS, and a hierarchy function p as defined above, we 
define a descendants function p': S -> 2^ as follows: 

{ \else 

p'(s) denotes only the substates of s, without the additional type and default state information. 

We extend the definition of p' to handle sets of states as arguments, too. For a 
subset S'e S we define: 

8. p' (S') := [J p' (s) , thus the extended function is p' : S u 2^ 2^ 

seS' 

Dennition: (root state) 

For a set of states S and a hierarchy function p as above, we define: 

9. s is a root state :<=> Vs'e S, s' ^ s : s ^ p' (s') 

notation: s g Root (S,p) 
Definition: (substate closure) 

For a set of states S, a state s e S, and a hierarchy function p as defined above, we 

define: 

10. p*(s):={s'GS|3nGlN:s'ep'(")(s) 

Note: p'^°^(s) denotes applying p'n times. 
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Definition: (Statechart) 

For S, E, A, T, p and S^jt defined as above, we define: 
SC = (S, E, A, T, p, SbJ is a statechart : 

|Root(S,p)| = l 

notation : Root(S, p) = {s„„, } 

(unique root state) 

• V s e S: 

p(s)= terminal 

V p(s) = (S^b » AND, < ). S,„b ^ { }, (S,„b , :Sand ) totally ordered set 

V p(s) = (S^b , XOR, Sdrf ), S,„b { }, Sdrf € s,„b 
(well-defined hierarchy function, default states) 

• VS€S,Si,S2 ep'(s):p*(si)np*(s2)9^{ }=>Si =83 

P'(s) = Ssub=^s^S^b 
(tree structure of states) 

• Sbu, c {s € S|p(s) = (S^b » XOR, Sjef )} for suitable S^b. s^ef 
(history states) 

• t = (Sjgy^g,e,S,3jggt ,a),t = (S jgy^j ,e,S f3jgj, ,a jjSjQyj^ ^ S source source ^ ^source 
=>t = t' 

(no two transitions shall share their event and their source states) 

• t = (S5(,^gg,e,S,2jggj,a),t =(S5(,„rgj s^O'^target '^^^souroe ^ ^'source source ^ ^source 
=>t = t' 

(no two transitions shall share their source states is one of them is associated 
with the empty event) 
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(S3,,,XOR,S,,,)AseS3,, 

(source states - except root state - and target states have to be recruited from 
XOR children) 

• t e T, t = (Sgo^^,g 5 ^? S^g^ggt , a), 

^ {s*| (s%hist)is a configuration a S^^^g^^ c S* j?^ { } 

(target state set has to be consistent, i.e. there is a configuration that contains 
the target state set) 

Thus, for (S, E, A, T, p, S^^J to be a statechart, one (and only one) root state 
(named S,^J exists. The hierarchy function p must be well-defined, default states must actually be 
chosen from the available sub states. Also, p must define a tree structure. This is ensured by the 
requirement that the sets of substates of sibling states are pairwise disjomt. History states can be 
chosen only from those states for which XOR decomposition is defined. Finally, a number of 
requirements are specified for transitions: they must have either different source sets or different 
events, the target and source states must be XOR children, and no transition must specify an 
inconsistent target set. 

Statechart Configuration: 

For a statechart SC = (S, E, A, T, p, ShiJ, a history function hist : S^^^^ S, hist 
well-defined, and a set S^ctive active states, we define: 

12. = (Sactive? ^Ist) Is a configuration : 

''root ^ ^active 

s e S,„i,„ p(s) = (S,„b, XOR, Sdef) => I {s' e S3„b | s'e S^^^i^e} | = 1 
s e S,^^e. P(s) = (Ssub> AND, < and) => V s' e S^^ : s' e S^^e 

S ^ ^active' P (^) ~ (^sub) ^sub ^active ~ { } 

hist(s) = Sh => p(s) = (s,ub, XOR, s^ef) and e s^^, 


PATENT 
99CR125/KE 


Thus, the designated root state is always active. For an active XOR parent state, 
one (and only one) of its substates is active, too. For an active AND parent state, all of its 
substates are active, too. For an inactive parent, all of its substates are inactive. The history 
function maps parent states to valid substates of the respective XOR decomposition. 

Definition: (Start Configuration) 

For a statechart SC = (S, E, A, T, p, S^J, we define the start configuration. 

13. Co : = (So, Msg, 

Where So is defined by induction as follows: 

• Sfoot ^ So 

• s G So, p(s) = (S,,b, XOR, Sdef) ^ Sdef e So 

• s e So, p(s) = (S,,b, AND, < ^nd) => Ssub Sq 

• no other states are in Sq 

The history function of the start configuration is defined by 

14. histo : Shi3, ^ S : s ^ s^,, if p(s) = (S,,^, XOR, s^ef) 

This maps an XOR parent to its defined default state. We have to show that this 
initial history function is well-defined. 
Lemma: 

15. histo : S^^^^ ^ S is well defined. 

Proof: By definition of the statechart SC, S^,, c {s g S | p(s) = (S.^^, XOR, s^ef) } . 
Thus, V s € S^,, : 3 s,,^ g S, S,,, e S : p(s) = (S,,^, XOR, s,,^) 

Statecharts Semantics 

The above description defines a formal model for specifying statecharts 50 in the 
state machine configurations. The above description defines a set of actions and events and 
determines when possible configurations for default are star configurations. The description below 
provides an exemplary embodiment of a state machine executing statecharts. The state machine 
exists in an original configuration and an input event results in a target configuration for the state 
machine. The target configuration can trigger zero or more available actions. According to this 
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embodiment, several rales are provided. First, the behavior of the state machine is predictable. 
For a given configuration in an input event, only one target configuration and one set of resulting 
actions can be valid (deterministic). Second, a list is provided for a set of actions. In this way, the 
order in which actions are triggered can be classified. The list, rather than a set of actions, allows 
the same action to be triggered by twice by one event (in parallel states of the state machine). 
Thfa-d, the target configuration adheres to the definition of the configuration. Generally, a function 
operates as follows: 

16. [SC]:(C,e)h^(C,n„ AL), 

with n, G IN, AL: {1 n^ ^ A} 
where SC is the statechart. 

Thus, a formal model to specify statecharts and state machine configurations is 
shown. In addition, a set of events and actions is defined. One of the possible configurations to be 
the default or start configuration is determined above. 

The actual execution of the statechart is discussed below. Wherein descriptions of 
the machine's operations as it takes an origin configuration and an input event and results in a 
target configuration, thereby triggering zero or more of the available actions. The behavior of a 
state machine shall be predictable. For a given configuration and an input event, only one target 
configuration and one set of resulting actions shall be valid. 

• The order in which the actions are triggered may be important. Thus, rather than a set of 
actions, a list is appropriate. This will also allow the same action to be triggered twice by 
one event (in parallel states of the machine). 

• The target configuration must adhere to the definition of a configuration. 

A function of the following type can be utilized: 

16. [SC]: (C,e)^(C',n„ AL), 
with n^ G IN, AL: {1 .. n, ^ A} 
SC is, the statechart. 

The semantics function (indicated by the [] brackets aroimd the actual syntactical 
statechart definition SC) depends on the actual statechart, C is the original configuration, C the 
target configuration. E is the input event being processed, possibly it is the empty event e^. n^ 
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specifies the number of resulting actions, whereas AL (action list) determines the actions 
themselves. Thus, [SC] will define the single-step behavior for a statechart SC . Several 
definitions have to be prepared before the semantics function can be specified. 

Definition: (hot states) 

For a Statechart SC=(S, E, A, T, p, S^J and a corresponding configuration 
C = (Sactive» hist), the set of potentially hot states is defined as 

1'^' Tc- ~ {(^source* ^' ^target? ^) I ^source ^ ^active} 

Tc denotes the transitions that could potentially be used when the next input event is 
received, i.e. the transitions whose source states are all active. Similarly, with an event cg E, hot 
states are defined as 

1^- e :={(Ssource5 ^target? ^) ^ | e'=e V c' = Cq} 

Tc.e denotes of course those elements of Tc that either match the specified event or 
that do not require an input event. In the latter case, the transition specifies the empty event e^. 

The set T^ e determines the transitions that could be used while a new input is being 
processed. Problems can arise when the order in which multiple transitions in Tc e are processed 
determines the order in which their associated actions are performed. Thus, the order has influence 
on the semantics and needs to be deterministic. 

Two transitions t^, t2 e Tc after tj has been processed and its target states have 
been activated, the source states of might no longer be active. That is because activation of new 
target states usually requires deactivation of siblings. In this case, cannot be processed any 
more. Therefore, choosing a predetermined execution order is even more important for the 
semantics, for not only the execution order of actions, but whether or not they are executed at all 
depends on it. 

The intermediate goal is therefore to define an order on the transitions. The first 
step, however, is to specify an order on the states of the Statechart. Execution is from left to right 
in parallel states (AND) and fi-om the lower to the higher levels of hierarchy (XOR, i.e. leafs first, 
root last). The XOR hierarchy is clearly visible by the hierarchy fiinction p; with XOR hierarchy, 
only one substate can be active at any time, which of course eliminates any potential non- 
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determinism. On the other hand, the order of parallel substates (AND) is defined by the < ^^d 
relation that comes with p: 

Definition: (order on states) 

For a Statechart SC=(S, E, A, T, p, Sjjist) an order on the states < c S x S is defined 

as follows: 

• Vs€S:s<s (reflexive) 

V s G S: p (s) = (S,,,, XOR, s^ef) =^ s' < s V s'g S,,^ 

• V s € S: p (s) = (S,,b, AND, <and) => V Si, Sj g S.^^, : Si<andS2^Si<S2 

ands'<s Vs'eS^^b 

• V(Si, S2) G <, (S2, S3) G < : (Si, S3) G < (transitive closure) 

Note that this order < does not define a totally ordered set on the states in S, That is 
because siblings in XOR substates are not ordered by <. However, these siblings are only mutually 
exclusively active in any valid configuration. No two of these siblings (or their descendants) can 
be active at the same time, thus there is no need for an order that exceeds the one given above. 

Lemma: 

For a Statechart SC = (S, E, A, T, p, Shi^J and an order < c S x S as defined above, 
for each valid configuration C = (Sactive, hist), (S^ctive? ^) is a totally ordered set. 
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Proof: 

A totally ordered set is reflexive, transitive, and for s, s' e Sactive- s < s' or s'< s 

1. V s G S^ctive- s < s by definition of < (reflexive) 

2. V q, r, s, e S^ctive^ q<r, r<s=>q<sby definition of < (transitive) 

3. Vs, s' €S,,,,,: 

a) s € p*(s'): s is a descendant of s', so there is n g IN, n>0: s g 
p'^"\s'), i.e., by applying p' n times we get down to the level of s. 
Therefore, there are states Si . . . s^_^ so that s < Si< . . . < Sn_i<s' by 
definition of <. Thus: s < s' (due to transitive definition of <). 

b) s' g p* (s): analogous 

c) else, i.e. neither s is a descendant of s' nor vice versa: 

s and s' have a lowest common ancestor s^^estor the hierarchy tree. 
This ancestor state must be of AND type because only this way both s 
and s' can be in s^etive- The order <^^jy of s^ncestor defines the order of s 
and s'. 

Thus, for any two states that can be active at the same time, there is always an order 
for these states. This order to defines another order, an order on sets of states: 

Defimtion: (order on sets of states) 

For a Statechart SC = (S, E, A, T, p, S^J, an order < e S x S as defined above and 
a subset S' c S so that (S', <) is a totally ordered set, we define an order <^^^ e 2'' x 2'' on sets of 
states. Let X and Y denote the subsets of S' that shall be compared; X = {x^, . . . , x„} and Y = 
{yi. • • • . Ym}- Because (S', <) is a totally ordered set, it can be assumed that x^ < . . . < x^ and yi 

< . < V 

19. X Y : a k 6 IN, k>0, k< min (n,m), so that X; = y; V i=l . . k-1 and x^<yy, 
and Xt-^Yy. or n < m and X; = yj V i = 1. . . n 
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This means that the smallest k-1 elements of both A and B are identical, and the one 
that is immediately following determines the order of the two sets. Should all n elements of the 
first set be identical to the first n elements of the second set, the first set is defined to be smaller. 

Deflnition: (order on transitions) 

For a Statechart SC=(S, E, A, T, p, Shist), a configuration C = (S^^tive. hist), an 
event e e E, hot transitions t, t' e Tc.e, t=(S,o^rce. S^^ge^, a), and t' = (S'^ource. e', a'), we 

define the order <j a T^^e ^ e by 

20. t ^-p t . <^ Sgpyj-j^g ^ggt S source 

Using the order <t, a set of hot transitions T^^t can be described as T^ot = {t^i, . . . 
t^n} where t^j < . . . < t^^- This order determines the execution order of the state machine. 

Having this order defined is a difference to conventional Statechart models. Where 
other models support the idea that transitions and actions are processed atomically, only to find out 
later that the implementation of such an ideal model causes a number of issues, the model respects 
right from the start the fact that execution on machines is serial. Thus, the semantics are always 
executable and well-defined. 

Activating an inactive State 

When an inactive state is activated due to a transition, the action associated with the 
transition is triggered after these events occur: 

• The new state has to become member of the active states set. 

• Any siblings of the new active (XOR) state (and their descendants) have to be deactivated. 
Note: The new state is among the target state set of a transition; therefore, we may assume 
that it is indeed an XOR child. 

• Descendants of the new active state have to be activated: for XOR states, activate the last 
recently active child (history function) for history states; otherwise, active the default child 
state. For AND states, activate all descendants. 

• Ancestors of the new state have be activated. Potential siblings of XOR ancestors need to 
be deactivated. 

• The history function has to be adjusted to reflect the new situation. 

The function that performs these steps is called activate: 
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21. Activate: 2^ X Starget (^active' Snew) ^ ^\ciiv& 

where S^,^,, = {s € S | 3 Sp,,ent ^ S: p (Sp,,ent)=(Ssub. XOR, s^^f) a s g S,J 

The activate function is only defined for states s^^^^ that are XOR children (only this 
subset qualifies for target states). 

The first utility function that is computed to determine the ancestors of a state, all 
the way up to the root state. This function identifies states that have to be activated in the 
hierarchy above the transition's target state: 

22. ancestors: S ^ 2^ : s i-^{s* e S | s e p*(s*)} 

The function returns all those states whose substate closure contams s, i.e. it returns 
all the ancestors of s. 

Next XOR Siblings of states are identified. This will be used to deactivate siblings 
(and their ancestors) of activated states: 

23. siblings : 2^ ^ 2^ S,^^^ {s g S | 3 Sp^^^nt ^ S: p is,,,,J=(S,,,, XOR, s^^f) a s g 

Ssub ^ ^origin ^ ^suh ^ { } A S G Sorigin} 

Thus, for a set of origin states the siblmgs function will return all those states that 
are siblings of at least one of the states in So^gin, excluding the trivial elements that are already 
contained in s^rigi^. 

Also, the new states that get activated below the triggered state must be determined. 
These are history states or, in absence of a defined history value, the default substates: 

24. desc Activate : S^2' : 

f { P (s) = terminal 

Ssub ^ ^s*.ssub descActivate(s*), p (s) = (S,,„ AND,<and) 

{sj u descActivate(Sj^, p (s) = (S^.^, XOR, s^ef) a s g a$^ = hist(s) 

{Sdef} ^ descActivate(Sdef), p (s) = (S^.^, XOR, s,,f) a s ^S.^^, 

^ Thus, the recursively defined desc Activate function terminates if the argument is a 

termmal state (leaf), or it returns the history/default substate for an XOR parent and all substates 
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for an AND parent. Unless a terminal state has been hit, descActivate is referenced recursively to 
also include states on lower levels of the hierarchy. 

Finally, the function definition for line 21 is delivered: 

25. activate: (S^,„ s^J i-> 
(Sactive ^ ancestors(s„ew)) \ P* (siblings(ancestors(s^J)) u descActivate (s^), 

^new ^ *^active 

S . , ? ^Ise 

*^active> ' 

Updating the History Function 

Once the set of active states has been changed, the history function as the second 
component of the configuration needs to be adjusted accordingly. History states are mapped to 
presently active substates if these exist; otherwise, the history function is defined by the formerly 
set value. With Sactive being the new configuration's set of active states and hist being the former 
history function, this works as follows: 

26. histSingleStepj^,Xs): = ^s,hiid, P (s) = (8,,^, XOR, s^^f). ^child ^ Sgubs ^chM ^ ^active 

hist(s), else 

The complete new history function for the new configuration is delivered by the 
following function: 

27. histUpdate : (S^ist ^ S) ^ (Shist^S) : hist histSingleStephist 

histUpdate will be used after changing the active states to generate the new history 
function, making a "snapshot" of the currently active states. 

Processing an Input Event 

Upon reception of a new input event e g E in the configuration C, the following has 

to happen: 

• determine the hot transitions Tq ^ 

• bring these transitions into their execution order as outlined above 
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• for each transition tj: 

if source states of tj active then 

activate target states of tj (multiple target states: in the order defined by <set) 
trigger action of ti 

end if 

end for 

The check for activity of the source states of a transition is necessary because 
activating a particular state in a prior iteration of the loop may have caused originally active states 
to become inactive. 

Definition: (transition semantics) 

For a Statechart SC = (S, E, A, T, p, S^,) and a transition t-=(S,^^,^,, e, S^,^,,, a), 
where the target states can be listed as St,,get={si . . . , sj and s^ < t the semantics of the 

transition t is defined as follows: 

28. [t] : 2^ 2^ X A u {noAction} : 

Sactive "> r (activate(activate(...(activate(S,etive' s^^Sj), . . . ),Sk),a), Ssource*=S,,ti,e 
L (^active. noAction), else 

A set of active states is mapped to a resulting set of active states and to the resulting 
action. Should the source states no longer be active, nothing happens, i.e., the active states are 
returned unchanged and no action is performed. 

Note: The order < is total on the set of target states because of the way we defined 
the Statechart SC. Recall that a target state set has to be consistent, i.e. there has to be a valid 
configuration that contains the target state set. For these configurations < does indeed define a total 
order on the states as demonstrated above. 

Finally, we can now specify the Statechart semantics. Recall that the semantics of a 
Statechart SC is a fimction [SC] : (C, e) (C, n^, AL) (see formula 16). 
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DeHnition: (Statechart semantics) 

For a Statechart SC - (S, E, A, T, p, S^J, we define the semantics function [SC] 

as follows: 

[SC] : ((S,,,,,hist), e) ^ ((S\,,,e,hist'), n,, AL), with n, g IN, AL:{1 n^^A} 
where 

• Tc.e denotes the hot states for a configuration C and an event e as defined in formula 18, and 
Tc.e can be listed as {t^ . . . , tk} with t^ < . . . < t^ 

• S',etive ' = Proji [tj (. . . (proji [ti](S,,,iJ). . . ) 

proji (Xi . . . , Xi) : =Xi is the projection to the i*^ element. 

• hist' : =histUpdated (hist) 

• addAction: IN x (IN^A) x A ^ IN x (IN^A): 

((n, AL), a) h->r (n+1, AL^^^y^{), a ^ noAction 
I- (n,AL) , else 

Notation: 

f[x/yj denotes the function that returns y as f(x) and f(x*) for all x* ^ x, i.e. the value for f(x) is 
replaced while the remaining function is not changed. addAction expands the definition of the 
action list AL to include a new action, which is appended to the end of the list. 

• action^ : = proj2 (ft] (proj^ [ti.i](...(proji ^1(8,,^,,)...))) 

denotes the action of the i* transition that is executed for an event 

• (n^, AL) := addAction (...(addAction (0, ±), action^) . . action^) 
is the resulting action list, where 1 denotes the undefined function. 

It is understood that while the detailed drawings, specific examples, and particular values given 
provide a preferred exemplary embodiment of the present invention, the preferred exemplary 
embodiment is for the purpose of illustration only. The method and apparatus of the invention is 
not limited to the precise details and conditions disclosed. For example, although particular 
graphical representation are shown and described, other types can be utilized. Various changes 
may be made to the details disclosed without departing from the spirit of the invention which is 
defined by the following claims. 
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CLAIMS 

What is claimed is: 

1. A statechart for use in the development of avionic software, the avionic software 
requiring deterministic behavior, the statechart comprising: 

a first state; 

a second state; and 

a third state, the third state including the first state and the second state, the first 
state being parallel to the second state, wherein the first state is ordered with respect to the 
second state, whereby the statechart does not allow parallel states to be unordered to ensure the 
deterministic behavior of the statechart. 

2. The statechart of claim 1 fiirther comprising: 

a fourth state in parallel with the first state and the second state and included 
within the third state, the third state being ordered with respect to the first state and the second 
state. 

3. The statechart of claim 2 further comprising: 

a fifth state in parallel with the first state, the second state and the fourth state 
and included within the third state, the fourth state being ordered with 'respect to the first state 
and the second state and the third state. 

4. The statechart of claim 1 further comprising: 

a history element disposed in the third state, the history element ensuring that 
the last exited state of the first state, and ;the second state is entered when the third state is 
entered. 
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5. The statechart of claim 4 wherein the history element includes a default setting 
indicating the first state or the second state. 

6. The statechart of claim 1 wherein the avionic software is a graphical flight 
planner. 

7. A modified Harel statechart formed on a computer, the modified Harel 
statechart comprising: 

a mathematical or graphical representation of a group of states, the group of 
states including a first state including a plurality of ordered parallel states, the mathematical 
representation ensuring deterministic operation. 

8. The modified Harel statechart of claim 7 wherein the ordered parallel states 
include history elements. 

9. The modified Harel statechart of claim 8 wherein the group of states are 
represented mathematically and graphically. 

10. A computer code for a statechart editor, the computer code comprising: 

code for generating a graphical representation of a state including parallel states; 

and 


code for ordering the parallel states. 
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11. The computer code of claim 10 wherein the parallel states are ordered to 
provide determinism for an avionic system. 

12. The computer code of claim 10 further comprising: 

code for preventing the entry of a non-ordered parallel state. 

13. The computer code of claim 10 further comprising code for providing a 
graphical representation of the ordering, the graphical representation of the ordering being a 
placement of the ordered parallel states or textual indication of the ordered parallel states. 

14. A method of providing avionic software, the method comprising: 
providing a graphical representation of a state including a plurality of parallel 

states, the parallel states being ordered with respect to each other, the parallel states being 
ordered so that only one of the parallel states is active in response to a particular event; and 

applying the mathematical or graphical representation to an execution engine to 
create the avionics software. 

15. The method of claim 14 wherem the avionics software is fully deterministic. 

16. The method of claim 15 wherein the graphical representation is a modified 
Harel statechart. 
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17. A statechart for use in the development of software for an application, the 
statechart comprising: 

a first state means for representing a first condition of the software in the 

application; 

a second state means for representing a second condition, the second condition 
being within the first state means; 

a third state means for representing a third condition, the third condition being 
within a first state means, the third state means being ordered with respect to the second state 
means. 

18. The statechart of claim 17 wherein the second state means and the thkd state 
means are entered upon occurrence of a same event. 

19. The statechart of claim 18 wherein the first state means, the second state means 
and the third state means include a history element. 

20. The statechart of claim 17 wherein the application is avionic control and the 
statechart is deterministic. 
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SYSTEM AND METHOD FOR DEVELOPING SOFTWARE UTILIZING 
DETERMINATIVE REPRESENTATIONS 

ABSTRACT 

A statechart includes a state having two or more parallel states. The two or 
more parallel states are ordered to ensure determinism for the system. The statecharts can be 
modified Harel statecharts. The statecharts can be utilized to generate avionics software. 
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